Vulnerability Bulletins

DSA-4216 prosody - security update

   
Affected software Debian
 
It was discovered that Prosody, a lightweight Jabber/XMPP server, doesnot properly validate client-provided parameters during XMPP streamrestarts, allowing authenticated users to override the realm associatedwith their session, potentially bypassing security policies and allowingimpersonation.

More info:

https://www.debian.org/security/2018/dsa-4216